JetBrains TeamCity HTML Injection and Information Disclosure Vulnerabilities
BID:66067
Info
JetBrains TeamCity HTML Injection and Information Disclosure Vulnerabilities
| Bugtraq ID: | 66067 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 06 2014 12:00AM |
| Updated: | Mar 06 2014 12:00AM |
| Credit: | Omar Kurt, Mavituna Security and vendor reported this issue. |
| Vulnerable: |
JetBrains TeamCity 8.0 |
| Not Vulnerable: |
JetBrains TeamCity 8.1 |
Discussion
JetBrains TeamCity HTML Injection and Information Disclosure Vulnerabilities
JetBrains TeamCity is prone to a HTML injection vulnerability and an information disclosure vulnerability.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials, to control how the site is rendered to the user or gain access to sensitive information. Other attacks are also possible.
TeamCity versions prior to 8.1 are vulnerable; other versions may also be affected.
JetBrains TeamCity is prone to a HTML injection vulnerability and an information disclosure vulnerability.
Successful exploits will allow attacker-supplied HTML and script code to run in the context of the affected browser, potentially allowing the attacker to steal cookie-based authentication credentials, to control how the site is rendered to the user or gain access to sensitive information. Other attacks are also possible.
TeamCity versions prior to 8.1 are vulnerable; other versions may also be affected.
Exploit / POC
JetBrains TeamCity HTML Injection and Information Disclosure Vulnerabilities
Attackers can exploit this issue using a browser or readily available tools.
Attackers can exploit this issue using a browser or readily available tools.